AddUser malware family
AddUser is a malware family tracked by MalwareAnalyzer by Cyble across 4 publicly analyzed samples. First seen 2026-08-04, most recently 2026-08-04. Observed ATT&CK techniques include T1112, T1543.003, T1105.
Corpus statistics
- Publicly analyzed samples: 4
- First seen: 2026-08-04
- Last seen: 2026-08-04
- Verdicts: malicious 4
- File types: pe 4
ATT&CK techniques used by AddUser
Extracted command-and-control infrastructure
- http://www.360.cn - 4 samples
Recent AddUser samples
- 1491ee21bb6c4ea324ebd14b0819818229ad9b3f69ab0a148d284cd71d287305 - malicious (2026-08-04)
- 47f271a9ef34722953ba40f84e0c41a9357617f9179da5210c614710a178feaf - malicious (2026-08-04)
- 55988cdd02203fa690737b6e6aca99ae0aeaff42ae0807ede503918304a182f7 - malicious (2026-08-04)
- b73c835b3f88069a628114e937dfe134309292ccf965223def43c15e9f51b71a - malicious (2026-08-04)
Frequently asked about AddUser
- What is AddUser?
- AddUser is a malware family tracked by MalwareAnalyzer by Cyble across 4 publicly analyzed samples. First seen 2026-08-04, most recently 2026-08-04. Observed ATT&CK techniques include T1112, T1543.003, T1105.
- How many AddUser samples have been analyzed?
- MalwareAnalyzer by Cyble holds 4 publicly analyzed samples attributed to AddUser, first seen 2026-08-04 and most recently 2026-08-04. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does AddUser use?
- Across our AddUser samples the most frequently observed techniques are T1112 (4), T1543.003 (4), T1105 (2). Counts are the number of analyzed samples in which each technique was observed.
- What file types does AddUser use?
- AddUser samples in this corpus are distributed as pe (4).
- Does AddUser use command-and-control infrastructure?
- Yes. 1 distinct command-and-control indicator has been extracted from AddUser samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is AddUser malicious?
- 4 of 4 analyzed AddUser samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends